Bugtraq: by author

301 messages starting May 11 01 and ending May 03 01
Date index | Thread index | Author index


Aaron Campbell

Re: Fun with IP Identification Field Values (Identifying Older MS Based OSs) Aaron Campbell (May 11)

Adam Laurie

Re: iplanet calendar server 5.0p2 exposes Netscape Admin Servermaster password Adam Laurie (May 01)

Adriano Dias

RE: NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error V ulnerability] Adriano Dias (May 16)
Microsoft IIS CGI Filename Decode Error V - How to Adriano Dias (May 17)

Adriano Maia

Microsoft IIS CGI Filename Decode Error Vulnerability Adriano Maia (May 16)

Albrecht Guenther

security hole in os groupware suite PHProjekt Albrecht Guenther (May 15)
security hole in os groupware suite PHProjekt Albrecht Guenther (May 14)

Aldo Albuquerque - Segurança de Sistemas

IIS Decode Aldo Albuquerque - Segurança de Sistemas (May 17)
Nsfocus advisory testing Aldo Albuquerque - Segurança de Sistemas (May 16)

aleph1

Re: RH7.0: man local gid 15 (man) exploit aleph1 (May 16)
Re: Administrivia: Move to EZMLM aleph1 (May 15)

Alliance Security Labs

ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS Alliance Security Labs (May 18)

altomo

Remote Desktop DoS altomo (May 16)

Amaury Jacquot

Re: Advisory for Spynet Chat Amaury Jacquot (May 08)

andreas junestam

def-2001-27: GuildFTPD Buffer Overflow and Memory Leak DoS andreas junestam (May 28)

Andrew Hilborne

Re: Solaris /usr/bin/mailx exploit (SPARC) Andrew Hilborne (May 15)

Andrew Thomas

RE: NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error V ulnerability Andrew Thomas (May 15)

Andrew Tridgell

Samba 2.0.9 released - 2.0.8 did NOT fix the hole Andrew Tridgell (May 10)

A . Ramos

Re: iis exploit (fixed) A . Ramos (May 16)

astral

Remote vulnerabilities in OmniHTTPd astral (May 26)

Axel Hammer

Logitech vulnerability (DoS, man-in-the-middle-attack) - Resend Axel Hammer (May 22)
Cable-Router AR220e Portmapper Security-Flaw Axel Hammer (May 16)
logitech wireless devices: man-in-the-middle attack Axel Hammer (May 16)

bashis

Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled. bashis (May 05)
Cisco HSRP Weakness/DoS bashis (May 03)
Re: Cisco HSRP Weakness/DoS bashis (May 05)

Ben Efros

Re: TWIG SQL query bugs Ben Efros (May 30)

Ben Laurie

Re: TWIG SQL query bugs Ben Laurie (May 31)

Brian

Re: IIS Decode Brian (May 18)

Bronek Kozicki

Re: .printer vulnerability needs execute perms? Bronek Kozicki (May 11)

bugtraq

Nortan Antivirus 2000 Poproxy.exe problem bugtraq (May 24)

bugzilla

[RHSA-2001:061-02] Updated nedit packages available bugzilla (May 10)
[RHSA-2001:063-02] Updated gnupg packages available bugzilla (May 17)
[RHSA-2001:069-02] Updated man package fixing security problems available bugzilla (May 21)
[RHSA-2001:065-05] New Zope packages are available bugzilla (May 15)
[RHSA-2001:044-08] New samba packages available to fix /tmp races bugzilla (May 15)
[RHSA-2001:070-02] Updated mktemp packages available bugzilla (May 21)
[RHSA-2001:058-04] Updated mount package available bugzilla (May 02)
[RHSA-2001:060-04] Updated Kerberos 5 packages available bugzilla (May 16)

ByteRage

Re: Winamp 2.6x / 2.7x buffer overflow ByteRage (May 11)
GuildFTPD v0.97 Directory Traversal / Weak password encryption ByteRage (May 26)
CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption ByteRage (May 28)
WFTPD 32-bit (X86) 3.00 R5 Directory Traversal / Buffer Overflow / DoS ByteRage (May 26)
Re: Microsoft Media Player ASX Parser buffer overflow vulnerability ByteRage (May 11)
WFTPD 32-bit (X86) 3.00 R5 Directory Traversal / Buffer Overflow / DoS ByteRage (May 24)

Cade Cairns

Vixie cron vulnerability Cade Cairns (May 08)

Caldera Support Information

Security Update: [CSSA-2001-018.0] samba /tmp problems Caldera Support Information (May 18)
Security update: [CSSA-2001-17.0] gnupg - private key retrieval vulnerability Caldera Support Information (May 18)

Casper Dik

Re: Solaris /usr/bin/mailx exploit (SPARC) Casper Dik (May 15)
Re: Announcing ptyfix Casper Dik (May 03)
Re: Solaris /usr/bin/mailx exploit (SPARC) Casper Dik (May 17)

Christopher Gerg

RE: Windows 2000 .printer remote overflow proof of concept exploit.... Christopher Gerg (May 16)

Chris Wilson

Security Bug in InoculateIT for Linux (fwd) Chris Wilson (May 25)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: More multiple vulnerabilities in CBOS Cisco Systems Product Security Incident Response Team (May 22)
Cisco Security Advisory: IOS Reload after Scanning Vulnerability Cisco Systems Product Security Incident Response Team (May 24)
Cisco Security Advisory: Cisco Content Service Switch 11000 Series FTP Vulnerability Cisco Systems Product Security Incident Response Team (May 17)

Colin Watson

Re: RH7.0: man local gid 15 (man) exploit Colin Watson (May 16)

Craig Bernstein

Re: Nortan Antivirus 2000 Poproxy.exe problem Craig Bernstein (May 28)

Cris Bailiff

'unicode' vs URL encoding. Cris Bailiff (May 30)

Crispin Cowan

Netscape Security Contact? Crispin Cowan (May 28)
Immunix OS Security Advisory Procedures Crispin Cowan (May 31)
FormatGuard Crispin Cowan (May 27)

Crist Clark

Re: Fun with IP Identification Field Values (Identifying Older MSBased OSs) Crist Clark (May 15)

Critical Watch Bugtraqqer

Microsoft IIS FTP DoS -- MS01-026 Critical Watch Bugtraqqer (May 16)

Crussaider

Windows 2000 .printer remote overflow - webexplt.pl problem! Crussaider (May 11)

Curt Wilson

IIS CGI Filename decode error = financial industry server vulnerability Curt Wilson (May 17)

Cyrus The Great

IIS4/5 CGI decode hole, [patched] perl exploit for win32/unix Cyrus The Great (May 16)
IIS5 .printer exploit ported to perl and win32 Cyrus The Great (May 15)

Cy Schubert - ITSD Open Systems Group

Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Cy Schubert - ITSD Open Systems Group (May 19)

d0gman !

RE: Microsoft IIS CGI Filename Decode Error Vulnerability d0gman ! (May 16)

Damir Rajnovic

Re: Cisco HSRP Weakness/DoS Damir Rajnovic (May 16)

Dan Astoorian

Re: Solaris /usr/bin/mailx exploit (SPARC) Dan Astoorian (May 15)

Dan Stromberg

Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Dan Stromberg (May 19)
Re: Returned post for bugtraq () securityfocus com Dan Stromberg (May 30)

dark spyrit

IIS 5 remote exploit. dark spyrit (May 03)

Darren Moffat

Re: in.fingerd follows sym-links on Solaris 8 Darren Moffat (May 28)

David Choi

Re: DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2) David Choi (May 16)

David Howe

Re: Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator David Howe (May 28)

David LeBlanc

Re: Permanently remove iis printer mapping David LeBlanc (May 03)

David Litchfield

Re: Windows 2000 .printer remote overflow proof of concept exploit David Litchfield (May 03)

David Wagner

Re: Mail delivery privileges David Wagner (May 21)

David Wheeler

"Flawfinder" available for use David Wheeler (May 21)

debian-security-announce

[SECURITY] [DSA-055-1] gftp remote exploit debian-security-announce (May 10)
[SECURITY] [DSA-054-1] cron local root exploit debian-security-announce (May 11)

Dehner, Ben

Re: Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Re mote SYSTEM Level Access) Dehner, Ben (May 03)

Denis Ducamp

Re: Fun with IP Identification Field Values (Identifying Older MS Based OSs) Denis Ducamp (May 11)

dethy

[synnergy] - Solaris mailtool(1) buffer overflow vulnerability dethy (May 28)

dex dex

dqs 3.2.7 local root exploit. dex dex (May 18)

Drake Diedrich

Re: dqs 3.2.7 local root exploit. Drake Diedrich (May 19)

eDvice Security Services

Aladdin eSafe Gateway Script-filtering Bypass through HTML tags eDvice Security Services (May 29)
Aladdin eSafe Gateway Filter Bypass - Updated Advisory eDvice Security Services (May 29)
Aladdin eSafe Gateway Script-filtering Bypass through Unicode Vulnerability eDvice Security Services (May 29)
Vulnerability discovered in SpearHead NetGap eDvice Security Services (May 28)
Aladdin eSafe Gateway script filter bypass eDvice Security Services (May 21)

Edwin Chiu

Re: Vixie cron vulnerability Edwin Chiu (May 08)

Elias Levy

COMPAQ Security Advisory SSRT1-85U Tru64 UNIX - xntpd overflow Elias Levy (May 02)
Administrivia: Mail Problems Elias Levy (May 09)
Predictable Initial Sequence Numbers Elias Levy (May 02)
SSRT0716-01 Security Advisory - Compaq Presario & Active-X Elias Levy (May 02)

EnGarde Secure Linux

[ESA-20010426-01] openssl vulnerabilities EnGarde Secure Linux (May 02)
[ESA-20010509-01] pine temporary file handling vulnerabilities EnGarde Secure Linux (May 28)
[ESA-20010508-01] glibc local vulnerability EnGarde Secure Linux (May 08)

Eric Chien

Re: Nortan Antivirus 2000 Poproxy.exe problem Eric Chien (May 28)

Erik Neuenschwander

Re: Personal Web Sharing remote stop Erik Neuenschwander (May 19)

e-Security Chap

[RE: NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error V ulnerability] e-Security Chap (May 16)

Eugene Tsyrklevich

Re: Webmin Doesn't Clean Env (root exploit) Eugene Tsyrklevich (May 30)

Filip Maertens

MS01-026 - proof of concept - Followup Filip Maertens (May 16)
IIS Exploit Filip Maertens (May 15)

fish stiqz

[synnergy] - GnuPG remote format string vulnerability fish stiqz (May 29)

Florian Weimer

Re: Announcing ptyfix Florian Weimer (May 02)
Re: [SECURITY] [DSA 052-1] New sendfile packages fix root exploit Florian Weimer (May 02)

Franklin DeMatto

RE: Nortan Antivirus 2000 Poproxy.exe problem Franklin DeMatto (May 28)
DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2) Franklin DeMatto (May 15)

gattaca

Re: Nortan Antivirus 2000 Poproxy.exe problem gattaca (May 28)

Georgi Guninski

IIS 5.0 PROPFIND DOS #2 Georgi Guninski (May 06)
Elevation of privileges with debug registers on Win2K Georgi Guninski (May 24)

Greg A. Woods

Re: Solaris /usr/bin/mailx exploit (SPARC) Greg A. Woods (May 15)
Re: Solaris /usr/bin/mailx exploit (SPARC) Greg A. Woods (May 17)
Re: Solaris /usr/bin/mailx exploit (SPARC) Greg A. Woods (May 16)
Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Greg A. Woods (May 19)
Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Greg A. Woods (May 18)
Re: Solaris /usr/bin/mailx exploit (SPARC) Greg A. Woods (May 18)

Greg KH

Immunix OS Security update for samba Greg KH (May 10)
Immunix OS Security update for minicom Greg KH (May 17)

Henrik Nordstrom

Re: Mail delivery privileges Henrik Nordstrom (May 19)

http-equiv () excite com

feeble.hey!dora.exploit part.II http-equiv () excite com (May 29)

Hux Flux

iis exploit (fixed) Hux Flux (May 16)

Ichinose Sayo

Becky! 2.00.05 Buffer Overflow Ichinose Sayo (May 15)

Immunix Security Team

Immunix OS Security update for man Immunix Security Team (May 31)
Immunix OS Security update for GnuPG Immunix Security Team (May 31)
Immunix OS Security update for kerberos Immunix Security Team (May 31)

inc

3COM OfficeConnect DSL router vulneratibilities inc (May 15)

IT Resource Center

security bulletins digest IT Resource Center (May 23)

James Renken

Re: 3COM OfficeConnect DSL router vulneratibilities James Renken (May 16)

Jarno Huuskonen

Imp-2.2.4 temporary files Jarno Huuskonen (May 31)

Jass Seljamaa

Rumpus FTP DoS Jass Seljamaa (May 15)
Personal Web Sharing remote stop Jass Seljamaa (May 15)

J. Bol

Re: in.fingerd follows sym-links on Solaris 8 J. Bol (May 28)

J. Nick Koston

Webmin Doesn't Clean Env (root exploit) J. Nick Koston (May 28)

Joep Vesseur

Re: in.fingerd follows sym-links on Solaris 8 Joep Vesseur (May 28)

joetesta

Vulnerabilities in CrushFTP Server joetesta (May 03)
Vulnerability in viewsrc.cgi joetesta (May 23)
Potential DOS Vulnerability in WFTPD joetesta (May 03)

Johann Klasek

Re: Solaris /usr/bin/mailx exploit (SPARC) Johann Klasek (May 15)

Jonas Eriksson

tmp-races in ARCservIT Unix Client Jonas Eriksson (May 18)
sendmail 8.11.4 and 8.12.0.Beta10 available (fwd) Jonas Eriksson (May 29)
HP OpenView NNM v6.1 buffer overflow Jonas Eriksson (May 23)
[Announce] Apache 1.3.20 Released Jonas Eriksson (May 22)
Apache Software Foundation Server compromised, resecured. (fwd) Jonas Eriksson (May 31)

Jose Nazario

solaris 2.6, 7 yppasswd vulnerability Jose Nazario (May 28)

Joshua Dodds

Re: Windows 2000 .printer remote overflow proof of concept exploit.... Joshua Dodds (May 15)

Juan Manuel Pascual Escriba

undocumented 3Com Netbuilder II SNMP ILMI commnity Juan Manuel Pascual Escriba (May 23)
undocumented 3com Netbuilder II SNMP ILMI vulnerability Juan Manuel Pascual Escriba (May 28)

Kevin Fu

Re: Netscape Security Contact? Kevin Fu (May 28)

KRFinisterre

Re: [SRT2001-10] - scoadmin /tmp issues KRFinisterre (May 23)

Kris Kennaway

Re: Vixie cron vulnerability Kris Kennaway (May 15)

Leif Jakob

Test for last IIS-escape vulnerability Leif Jakob (May 16)

Lincoln Yeoh

Re: Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access) Lincoln Yeoh (May 02)

Linux Mandrake Security Team

MDKSA-2001:049 - Zope update Linux Mandrake Security Team (May 14)
MDKSA-2001:053 - gnupg update Linux Mandrake Security Team (May 31)
[Security Announce] MDKSA-2001:040-1 - samba update Linux Mandrake Security Team (May 21)
MDKSA-2001:050 - vixie-cron update Linux Mandrake Security Team (May 14)
MDKSA-2001:046-1 - kdelibs update Linux Mandrake Security Team (May 25)
MDKSA-2001:047-1 - pine update Linux Mandrake Security Team (May 16)
MDKSA-2001:052 - ncurses update Linux Mandrake Security Team (May 25)
MDKSA-2001:048 - cups update Linux Mandrake Security Team (May 14)
MDKSA-2001:047 - pine update Linux Mandrake Security Team (May 08)
[Security Announce] MDKSA-2001:033-2 - openssh update Linux Mandrake Security Team (May 21)

Loggins, Ron G

Tektronix (Xerox) PhaserLink 850 Webserver Vulnerability (NEW) Loggins, Ron G (May 23)

Lukasz Luzar

in.fingerd follows sym-links on Solaris 8 Lukasz Luzar (May 24)
Re: in.fingerd follows sym-links on Solaris 8 Lukasz Luzar (May 25)

Luki Rustianto

TWIG SQL query bugs Luki Rustianto (May 28)

Lyle Seaman

Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Lyle Seaman (May 19)

Lyndon Nerenberg

Re: in.fingerd follows sym-links on Solaris 8 Lyndon Nerenberg (May 24)

Magosányi

Re: insecure signal handler design Magosányi (May 30)

Marc Maiffret

RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS Marc Maiffret (May 19)
iPlanet - Netscape Enterprise Web Publisher Buffer Overflow Marc Maiffret (May 16)
Windows 2000 .printer remote overflow proof of concept exploit Marc Maiffret (May 02)
Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access) Marc Maiffret (May 01)

Marcus Meissner

Re: Unsafe assumptions (Re: Mail delivery...) Marcus Meissner (May 21)
Re: Webmin Doesn't Clean Env (root exploit) Marcus Meissner (May 29)

mark

.printer vulnerability needs execute perms? mark (May 03)

Marshal

directorypro.cgi , directory traversal Marshal (May 28)

Martin O'Neal

Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x password restrictions Martin O'Neal (May 15)
Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x database configuration Martin O'Neal (May 15)

marvin

Re: Fun with IP Identification Field Values (Identifying Older MS Based OSs) marvin (May 11)

Matthew Connor

RE: Nortan Antivirus 2000 Poproxy.exe problem Matthew Connor (May 24)

Matthew Firth

Re: Proof of concept DoS against novell border manager enterprise edition 3.5 Matthew Firth (May 01)

Matthew R. Potter

Re: in.fingerd follows sym-links on Solaris 8 Matthew R. Potter (May 24)

Matt Power

Re: solaris 2.6, 7 yppasswd vulnerability Matt Power (May 31)
Re: Windows 2000 .printer remote overflow proof of concept exploit Matt Power (May 02)

Matt Rudge

RE: About the new IIS %252c bug. Matt Rudge (May 16)

Matt Schalit

Re: [SRT2001-10] - scoadmin /tmp issues Matt Schalit (May 23)

Melanie Abbas

Oracle's ADI 7.1.1.10.1 Major security hole Melanie Abbas (May 07)

Michael Vassiliadis

IIS Decode Michael Vassiliadis (May 17)

Michal Zalewski

insecure signal handler design Michal Zalewski (May 29)
Re: Vixie cron vulnerability Michal Zalewski (May 08)
Unsafe Signal Handling in Sendmail Michal Zalewski (May 29)

Microsoft Product Security

Microsoft Security Bulletin MS01-027 Microsoft Product Security (May 16)
Microsoft Security Bulletin MS00-079 (version 2.0) Microsoft Product Security (May 25)
Microsoft Security Bulletin MS01-026 Microsoft Product Security (May 15)
Microsoft Security Bulletin MS01-028 Microsoft Product Security (May 21)
Microsoft Security Bulletin MS01-023 Microsoft Product Security (May 01)

mparcens

Yahoo/Hotmail scripting vulnerability, worm propagation mparcens (May 31)

neme-dhc

Advisory for MP3Mystic neme-dhc (May 08)
Advisory for Spynet Chat neme-dhc (May 08)
About the new IIS %252c bug. neme-dhc (May 16)
Advisory for Vdns neme-dhc (May 08)
Advisory for Jana server neme-dhc (May 14)
Advisory for Electrocomm 2.0 neme-dhc (May 08)
Advisory for Freestyle Chat server neme-dhc (May 25)
Advisory for A1Stats neme-dhc (May 08)

Nobuo Miwa

Re: TrendMicro Interscan VirusWall RegGo.dll BOf Nobuo Miwa (May 30)
TrendMicro Interscan VirusWall RegGo.dll BOf Nobuo Miwa (May 18)
Re: Windows 2000 .printer remote overflow proof ofconcept exploit Nobuo Miwa (May 03)

Nsfocus Security Team

NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability Nsfocus Security Team (May 15)
Re: NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability Nsfocus Security Team (May 17)

Ofir Arkin

Fun with IP Identification Field Values (Identifying Older MS Based OSs) Ofir Arkin (May 07)
Several Misbehaviors with the ICMP implementation (and the 'ping' utility) with MS based operating systems Ofir Arkin (May 03)
Fingerprinting Linux Kernel 2.4.x based machines using ICMP (and IPID) Ofir Arkin (May 16)

Olaf Kirch

Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Olaf Kirch (May 18)
Re: Vixie cron vulnerability Olaf Kirch (May 15)
Re: RH7.0: man local gid 15 (man) exploit Olaf Kirch (May 15)

Olaf Titz

Unsafe assumptions (Re: Mail delivery...) Olaf Titz (May 19)

Oracle Security Alerts

Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator Oracle Security Alerts (May 22)

Pablo Sor

Solaris mailx Vulnerability Pablo Sor (May 02)

Paul Cardon

Re: [BUGTRAQ] Windows 2000 .printer remote overflow - webexplt.plproblem! Paul Cardon (May 15)

Pauli Ojanpera

Microsoft Windows Media Player Buffer Overflow Vulnerability Pauli Ojanpera (May 28)
Microsoft Media Player ASX Parser buffer overflow vulnerability Pauli Ojanpera (May 02)

Paul Szabo

Announcing ptyfix Paul Szabo (May 01)

Pavel Machek

Re: Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator Pavel Machek (May 25)

Peter Bierman

Re: Personal Web Sharing remote stop Peter Bierman (May 16)

Peter Gründl

def-2001-26: IIS WebDav Lock Method Memory Leak DoS Peter Gründl (May 17)
def-2001-24: Windows 2000 Kerberos DoS Peter Gründl (May 09)
def-2001-25: Carello E-Commerce Arbitrary Command Execution Peter Gründl (May 15)

Peter W

Re: Mail delivery privileges Peter W (May 19)

Phillip Renouf

Re: Permanently remove iis printer mapping Phillip Renouf (May 03)

PJ

Re: RH7.0: man local gid 15 (man) exploit PJ (May 17)

Progeny Security Team

PROGENY-SA-2001-13: gFTP client potentially vulnerable to attack Progeny Security Team (May 10)

psheep

Sendfile daemon bugs psheep (May 15)

railwayclubposse

Re: Permanently remove iis printer mapping railwayclubposse (May 03)
Permanently remove iis printer mapping railwayclubposse (May 02)

RATS Development Team

ANNOUNCEMENT: RATS-0.9 (C/C++ Security Scanner) RATS Development Team (May 21)

Richard Johnson

[SRT2001-09] - vi and crontab -e /tmp issues Richard Johnson (May 22)
[SRT2001-10] - scoadmin /tmp issues Richard Johnson (May 22)
[SRT2001-10] - scoadmin /tmp issues Richard Johnson (May 22)

Rich Lafferty

MUAs that delete spoolfiles (was Solaris /usr/bin/mailx exploit (SPARC)) Rich Lafferty (May 16)

Robert Cardona

Netscape Enterprise Server 4 Method and URI overflow Robert Cardona (May 19)

Roman Drahtmueller

SuSE Security Announcement: man (SuSE-SA:2001:019) Roman Drahtmueller (May 29)
SuSE Security Announcement: cron (SuSE-SA:2001:17) Roman Drahtmueller (May 16)
SuSE Security Announcement: kernel (SuSE-SA:2001:18) Roman Drahtmueller (May 17)
Re: dqs 3.2.7 local root exploit. Roman Drahtmueller (May 19)

Ron Trenka

Re: Personal Web Sharing remote stop Ron Trenka (May 16)

Russ

Re: Windows 2000 .printer remote overflow proof of concept exploi t Russ (May 03)

Ryan Fox

Re: TWIG SQL query bugs Ryan Fox (May 31)

Santi Claus

iPlanet Web Server 4.1 SP 4-7 Product Alert Santi Claus (May 15)

SChoe

RE: [synnergy] - Solaris mailtool(1) buffer overflow vulnerability SChoe (May 30)

Sebastian Krahmer

SuSE Security Announcement: cron Sebastian Krahmer (May 15)

Security COnfera

UNICODE2 (2708) Security COnfera (May 17)

security-officer

NetBSD Security Advisory 2001-006: Denial of service using bogus fragmented IPv4 packets security-officer (May 30)
NetBSD Security Advisory 2001-007: IP Filter may incorrectly pass packets security-officer (May 30)
NetBSD Security Advisory 2001-008: Processes can gain "Supervisor" privileges on sh3. security-officer (May 30)

SGI Security Coordinator

IRIX rpc.espd Buffer Overflow SGI Security Coordinator (May 15)

Shawn Kleinart

Re: Windows 2000 .printer remote overflow proof of concept exploit.... Shawn Kleinart (May 11)

Siberian

IPC@Chip Security Siberian (May 24)

SNS Research

SpyAnywhere Authentication Bypassing Vulnerabilities SNS Research (May 22)
OmniHTTPd Pro Denial of Service Vulnerability SNS Research (May 16)
DynFX POPd Denial of Service Vulnerability SNS Research (May 29)
Denicomp REXECD/RSHD Denial of Service Vulnerability SNS Research (May 11)
SpoonFTP Buffer Overflow Vulnerabilities SNS Research (May 30)

solar

Re: RH7.0: man local gid 15 (man) exploit solar (May 15)

SosPiro

Vulnerabilty in TYPsoft FTP server SosPiro (May 11)

Stefan Laudat

Re: Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled. Stefan Laudat (May 07)

Stephen Shirley

Re: RH7.0: man local gid 15 (man) exploit Stephen Shirley (May 16)

Steven M. Bellovin

Re: Cisco HSRP Weakness/DoS Steven M. Bellovin (May 03)
Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Steven M. Bellovin (May 18)

Sym Security

Re: Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x database configuration Sym Security (May 16)

Tamer Sahin

Tamersahin.net Security Announcement: Debian 2.2 is 2.2r3 Ftpd Daemon Buffer Owerflow Vulnerability Tamer Sahin (May 18)

Terje Bless

Re: Personal Web Sharing remote stop Terje Bless (May 16)
Re: Personal Web Sharing remote stop Terje Bless (May 16)
Re: Personal Web Sharing remote stop Terje Bless (May 17)

Thomas Dullien

Re: x86 vulnerability ? Thomas Dullien (Apr 30)

Tobias J. Kreidl

Re: Solaris /usr/bin/mailx exploit (SPARC) Tobias J. Kreidl (May 16)

tobozo tagada

PHPSlash : potential vulnerability in URL blocks tobozo tagada (May 16)

Todd Ransom

Re: Permanently remove iis printer mapping Todd Ransom (May 03)

Tom Laermans

RE: Nortan Antivirus 2000 Poproxy.exe problem Tom Laermans (May 28)
Re: Winamp 2.6x / 2.7x buffer overflow Tom Laermans (May 04)

Tom Tom

Hexyn / Securax Advisory #15,16,17,18,19 Tom Tom (May 14)

tsl

TSLSA-2001-0006: Samba tsl (May 25)

TurboLinux Security Team

Turbolinux Security Advisories TurboLinux Security Team (May 18)

Turner, Keith

How to remove .printer mapping (WAS RE: Permanently remove IIS pr inter mapping) Turner, Keith (May 03)

venomous

another exploit for cfingerd. venomous (May 11)

Wanderley J. Abreu Jr.

Re: Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access) Wanderley J. Abreu Jr. (May 02)

Wichert Akkerman

Re: Vixie cron vulnerability Wichert Akkerman (May 15)

Wietse Venema

Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Wietse Venema (May 18)
Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit) Wietse Venema (May 19)

X-Force

ISS Advisory: Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure X-Force (May 15)

yehuda

%25c double-parse vulnerability exploitable via email yehuda (May 16)

Zarêbski

Re: RH7.0: man local gid 15 (man) exploit [UNCONFIRMED] Zarêbski (May 15)

zenith parsec

RH 7.0:/usr/bin/man exploit: gid man + more zenith parsec (May 14)
minicom exploit zenith parsec (May 03)